CVE-2025-7739: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditions, could have allowed authenticated users to achieve stored cross-site scripting by injecting malicious HTML content in scoped label descriptions.
Other sources
GitLab has remediated an issue that, under certain conditions, could have allowed authenticated users to achieve stored cross-site scripting by injecting malicious HTML content in scoped label descriptions.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-7739?
CVE-2025-7739 is classified as a medium severity vulnerability due to the risk of stored cross-site scripting.
How do I fix CVE-2025-7739?
To fix CVE-2025-7739, upgrade GitLab CE/EE to version 18.2.2 or later.
Who is affected by CVE-2025-7739?
CVE-2025-7739 affects all versions of GitLab CE/EE from 18.2 before 18.2.2.
What type of vulnerability is CVE-2025-7739?
CVE-2025-7739 is a stored cross-site scripting (XSS) vulnerability.
Can authenticated users exploit CVE-2025-7739?
Yes, authenticated users can exploit CVE-2025-7739 by injecting malicious HTML content in scoped label descriptions.